Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=grassroots.hk
Issuer
C=US, O=Let's Encrypt, CN=R12
Valid From
May 02, 2026
Valid Until
July 31, 2026
84 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
82:AB:6E:5A:57:AA:98:4A:40:34:6B:D9:07:BE:8F:DD:48:A7:5E:3B:22:B4:97:F7:89:9A:E3:04:86:8F:20:FB
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
88 domains
sung1.com
*.sung1.com
333788.cc
*.333788.cc
35816.me
*.35816.me
420.irish
*.420.irish
872154.cc
*.872154.cc
95944.locker
*.95944.locker
aarpp.com
*.aarpp.com
*.img1-fg.aarpp.com
aduicesknowfasun.world
*.aduicesknowfasun.world
bjcourtage.fr
*.bjcourtage.fr
dharwad.com
*.dharwad.com
*.im.dharwad.com
*.ww17.dharwad.com
*.www.dharwad.com
dhlgrp.com
*.dhlgrp.com
eclipsemancer212.top
*.eclipsemancer212.top
font-spider.org
*.font-spider.org
grassroots.hk
*.grassroots.hk
*.mail.grassroots.hk
hanuliving.com
*.hanuliving.com
hucin.com
*.hucin.com
*.id.hucin.com
kdlybxi.cc
*.kdlybxi.cc
*.backup.mytholmroyd.com
*.blog.mytholmroyd.com
*.crm.mytholmroyd.com
mytholmroyd.com
*.mytholmroyd.com
*.sitemaps.mytholmroyd.com
*.ww16.mytholmroyd.com
*.ww25.mytholmroyd.com
*.ww38.mytholmroyd.com
neoaction984.info
*.neoaction984.info
nietvz.cyou
*.nietvz.cyou
ninlayatcasino.com
*.ninlayatcasino.com
nomiyama.com
*.nomiyama.com
*.ww25.nomiyama.com
oyxkpk.auction
*.oyxkpk.auction
pixelgame670.shop
*.pixelgame670.shop
premiumgetaways.xyz
*.premiumgetaways.xyz
rkhpl.pink
*.rkhpl.pink
silver-single.com
*.silver-single.com
thehosthaven.co.uk
*.thehosthaven.co.uk
trymsp-quotes.com
*.trymsp-quotes.com
vullkancasinopl.com
*.vullkancasinopl.com
w-ww.xyz
*.w-ww.xyz
weddingbeacon.beauty
*.weddingbeacon.beauty
yieldance.com
*.yieldance.com
yj5xxjt.top
*.yj5xxjt.top
zehady.club
*.zehady.club
zk-9-9-9.cc
*.zk-9-9-9.cc
zzz2372.cc
*.zzz2372.cc
Other domains in certificate